Mailinglist Archive: opensuse-factory (1029 mails)

< Previous Next >
Re: [opensuse-factory] Secure Boot 13.1 RC2
  • From: Günther J. Niederwimmer <gjn@xxxxxxxxxxx>
  • Date: Wed, 06 Nov 2013 11:54:38 +0100
  • Message-id: <2504366.EpYjVccfW5@techz>
Hello,

Am Mittwoch, 6. November 2013, 18:35:47 schrieb Gary Ching-Pang Lin:
On Wed, Nov 06, 2013 at 11:22:43AM +0100, Günther J. Niederwimmer wrote:
Am Mittwoch, 6. November 2013, 15:32:52 schrieb Gary Ching-Pang Lin:
On Wed, Nov 06, 2013 at 07:47:40AM +0100, Günther J. Niederwimmer wrote:
Am Mittwoch, 6. November 2013, 12:16:09 schrieb Gary Ching-Pang Lin:
On Tue, Nov 05, 2013 at 11:10:53AM +0100, Günther J. Niederwimmer
wrote:
can any tell me, is it possible to Install with active secure
boot?

On my system ASUS P8C WS it is not :(.

I have installed a W8 on this system, with secure boot.

With active secure boot it is not possible to start a uEFI
Installation
from DVD, when it is possible the Installation is starting in
"normal"
Mode.

Did you see the bootloader menu or the machine just refuse to boot
from
DVD?>

NO, I mean it is near to find the bootloader menu, the cursor is a
moment
on the place for uEFI Bott (small Window with uEFI Boot)

Could you try the following instructions?

1. open "yast bootloader" and make sure that "Enable Secure Boot
Support" is checked

2. replace shim.efi
$ dd if=/usr/lib64/efi/shim.efi of=shim.efi bs=1 count=1378256
$ sudo mv shim.efi /boot/efi/EFI/opensuse/shim.efi

3. reboot and enable secure boot in UEFI


4. boot the system

Please make sure UEFI boot the bootentry "opensuse-secureboot" instead
of
"opensuse"

Bad News ...

I have in the Bios the Entry

opensuse-secureboot
opensuse
Windows Bootmanager

With enabled Secure Boot ONLY Windows Bootmanager is starting ?

Can / shud I do insert the Certificat per Hand in the Secure Boot Manager
?

I have many Options to insert Keys / Certivicats with enabled Secure Boot.

Something is going wrong on the system :(.

That's weird. The MS signature in shim.efi should work :-\
Could you copy /sys/firmware/efi/efivars/db-* to a file and upload it to
somewhere?
Perhaps you could also try to upgrade UEFI.

I uploaded the Files to Bug 848797

Upgrade UEFI ?

I hope I found a script to learn this ;)

With disabled secure Boot I have this in efibootmgr ?

efibootmgr -v

BootCurrent: 0002
Timeout: 0 seconds
BootOrder: 0002,0000,0001,0008,0009
Boot0000* opensuse HD(2,96800,32000,7df6df22-9010-493d-8808-
dc97218f544d)File(\EFI\opensuse\grubx64.efi)
Boot0001* Windows Boot Manager HD(2,96800,32000,7df6df22-9010-493d-8808-
dc97218f544d)File(\EFI\Microsoft\Boot\bootmgfw.efi)WINDOWS.........x...B.C
.D.O.B.J.E.C.T.=.
{.9.d.e.a.8.6.2.c.-.5.c.d.d.-.4.e.7.0.-.a.c.c.1.-.f.3.2.b.3.4.4.d.4.7.9.5
.}...s................ Boot0002* opensuse-secureboot
HD(2,96800,32000,7df6df22-9010-493d-8808-
dc97218f544d)File(\EFI\opensuse\shim.efi)
Boot0008* CD/DVD Drive BIOS(3,0,00)AMGOAMNO........o.A.T.A.P.I. . .
.i.H.A.S.1.2.4. . .
.W....................A...........................>..Gd-.;.A..MQ..L.5.3.4.
2.0.6. .2.D.2.3.8.6.1.0.5.5.8.7.0......AMBO
Boot0009* Hard Drive BIOS(2,0,00)AMGOAMNO........o.W.D.C.
.W.D.1.0.0.2.F.A.E.X.-.0.0.Z.3.A.0....................A...................
........>..Gd-.;.A..MQ..L. . . . .W.
.-.D.C.W.T.A.C.R.5.3.4.6.1.8......AMBO

With deactivatet Secure Boot it is possible to install in uEFI
Mode.
When
I
activate secure Boot after the Installation in the oS the system
is
nerer
starting.

Only when I deactivate Secure Boot in the Bios, oS is starting
again
in
uEFI mode.

--
mit freundlichen Grüssen / best Regards,

Günther J. Niederwimmer
--
To unsubscribe, e-mail: opensuse-factory+unsubscribe@xxxxxxxxxxxx
To contact the owner, e-mail: opensuse-factory+owner@xxxxxxxxxxxx

< Previous Next >